CVE-2023-22707: WordPress Greenshift – animation and page builder blocks Plugin <= 4.9.9 is vulnerable to Cross Site Scripting (XSS)
Published Mar 27, 2023
·Updated
Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin <= 4.9.9 versions.
Affected Software
2 affected components
Greenshiftwp Greenshift - Animation And Page Builder Blocks Wordpress<=4.9.9
Wpsoul Greenshift Wordpress<=4.9.9
Remediation
Information
Update to 5.0 or a higher version.
Event History
Mar 27, 2023
CVE Published
via MITRE·02:05 PM
Data Sourced
via MITRE·02:05 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22707.
2
What is the title of this vulnerability?
The title of this vulnerability is Auth. (author+) Cross-Site Scripting (XSS) vulnerability in Wpsoul Greenshift – animation and page builder blocks plugin.
3
What is the affected software by this vulnerability?
The affected software by this vulnerability is Greenshiftwp Greenshift - Animation And Page Builder Blocks plugin versions up to 4.9.9.
4
What is the severity of CVE-2023-22707?
The severity of CVE-2023-22707 is medium with a CVSS score of 5.4.
5
How can I fix this vulnerability?
To fix this vulnerability, update to a version of Greenshiftwp Greenshift - Animation And Page Builder Blocks plugin higher than 4.9.9.